GHSA-52v4-wxrx-gjjm

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-52v4-wxrx-gjjm/GHSA-52v4-wxrx-gjjm.json
Aliases
  • CVE-2022-41251
Published
2022-09-22T00:00:26Z
Modified
2023-03-18T05:56:07.819418Z
Details

A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

References

Affected packages

Maven / org.jenkins-ci.plugins:apprenda

org.jenkins-ci.plugins:apprenda

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

2.*

2.1.0
2.1.1
2.1.2
2.2.0

Database specific

{
    "last_known_affected_version_range": "<= 2.2.0"
}